Trust Wallet Extension Backdoor: v2.68 Malicious Code Injection Analysis
In December 2025, Trust Wallet Browser Extension v2.68 was found to contain malicious backdoor code. The attacker modified the extension's source to exfiltrate users' seed phrases and private keys to the malicious domain metrics-trustwallet.com. This article dissects the malicious code and reconstructs the attack chain, concluding that this is an APT-level targeted supply chain attack.